EDBT 2026 Demo / reviewers in the wild / expert
Weiping Wang 0003
dblp:72/4134-3
· DBLP profile ↗
57ranked-venue papers
8as first author
33since 2021 · last 2026
0000-0001-5255-5639ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 3 first-author · 12 since 2021Security and privacy · 20 · 3 first-author · 15 since 2021Systems, architecture and hardware · 6 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorTheory of computation · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HHBT: DNS tunneling detection via hybrid hierarchical bidirectional transformer
Shilei Kuang, Weiping Wang 0003, Yongfei Ye, Lingzhi Peng |
Comput. Networks | 2 |
| 2025 | A Period-Adaptive Traffic Fingerprint-Based Method for Smart Home Device IdentificationabstractWith the widespread adoption of smart home devices, there is a growing need for third-party device monitoring. Rapidly identifying device types from online traffic is essential for timely device detection, serving as a prerequisite for effective device supervision. As most smart home devices employ proprietary protocols, their communication traffic often lacks distinctive payload content. Existing methods typically rely on statistical features of data packets in idle traffic, combined with classification learning models, and commonly use fixed-time-window sampling for data collection. However, idle traffic from devices comprises multiple session flows, each often exhibiting distinct periodicity, which can lead to inaccurate feature extraction when fixed-length sampling is applied. To address this, we propose a smart home device identification method based on period-adaptive traffic fingerprinting. This method utilizes Fourier transform to analyze the periodicity of session flows, enabling adaptive partitioning of traffic samples based on their periodic characteristics. For rapid identification, key packets in the periodic traffic are first identified through clustering, followed by the extraction of packet header features and locality-sensitive hashing of the payload to construct packet-level traffic fingerprints. A hierarchical matching mechanism based on header and payload features is then employed to achieve device type identification. Experimental results on a public dataset demonstrate that the proposed method achieves an identification accuracy of 98.82%, outperforming existing baseline methods. In real-world smart home scenarios, the method enables rapid packet-level matching, providing identification results before a complete traffic period is reached, thus offering a responsive and efficient solution for device monitoring. Yingjie Hu 0005, Weiping Wang 0003, Shigeng Zhang, Hong Song 0004, Shilei Kuang |
ACSAC | 2 |
| 2025 | Physically Robust and Imperceptible Adversarial Examples Generation Based on FrequencyabstractAdversarial examples generated in digital space may fail to work in the physical world because the recapture process will ruin the adversarial property of the examples. Several approaches have been proposed to generate adversarial examples that can survive in the physical world, they however either introduce markedly perceptible patterns (e.g., adversarial patches) or suffer from a low attack success rate due to improper perturbation propagation. In this work, we propose PRIA, a frequency-based approach to generating Physically Robust and Imperceptible Adversarial examples. PRIA reforms the pipeline of perturbation generation such that adversarial property of the generated examples retains after the recapture process. The experimental results reveal that PRIA outperforms state-of-the-art solutions, improves the attack success rate in the physical world by up to 19%, and meanwhile achieves the highest perceptual quality. Chengyao Hua, Shigeng Zhang, Xuan Liu 0001, Senzhang Wang, Weiping Wang 0003, Kai Chen 0012 |
ICASSP | 6 |
| 2025 | MPTM: A Multiple Perturbation Training Method to Generate Adversarial Traffic in Byte SpaceabstractThe wide adoption of encryption network traffic protocols, such as TLS/SSL, poses great challenges in the detection and recognition of network traffic. Recently, deep learning techniques have been exploited to detect malicious encrypted traffic. While achieving good performance, deep learning models can be bypassed due to their vulnerabilities to adversarial attacks. There has been some work on generating adversarial traffic to evade deep learning-based systems, however, they fail to generate traffic that complies with network constraints and does not work in practical scenarios. In this paper, we propose a method that can generate legitimate traffic and evade deep models in practical scenarios. The effectiveness of the method comes from two novel designs. First, the perturbations are added to only the payload field to generate legitimate packets. Second, the perturbations are generated in a way that adversarial examples with different multiple of the perturbations can both evade the detection system. Thus, the traffic generated with our method can be restored while all previous works fail to do so. We further designed a joint training method to improve the evasion rate of the generated traffic. Experimental results demonstrated that traffic generated by our method can evade state-of-the-art deep learning detection models with an overall escape success rate of higher than 94 %. Shigeng Zhang, Weiping Wang 0003, Xuan Liu 0001 |
IWQoS | 3 |
| 2025 | GTIBS: secure smart home monitoring through gateway traffic analysis and behavioral signature identification
Yingjie Hu 0005, Weiping Wang 0003, Shigeng Zhang |
Appl. Intell. | 2 |
| 2025 | ZipAST: Enhancing malicious JavaScript detection with sequence compression
Zixian Chen, Weiping Wang 0003, Shigeng Zhang |
Comput. Secur. | 2 |
| 2025 | ProvGOutLiner: A lightweight anomaly detection method based on process behavior features within provenance graphs
Weiping Wang 0003, Hong Song 0004, Kai Chen 0012, Shigeng Zhang |
Comput. Secur. | 1 |
| 2025 | Tactics and Techniques Text Classification Based on Adversarial Contrastive Learning and Meta-PathabstractTactics and techniques information in Cyber Threat Intelligence (CTI) represent the objectives of attackers and the means through which these objectives are achieved. The classification of tactics and techniques descriptions in CTI has been extensively studied to assist security experts in interpreting attack patterns. Although many recent studies have applied various deep learning methods to enhance classification performance, they mainly focus on improving performance from an average or top perspective. However, the imbalance between tactical and technical tag samples, as well as text sparsity, may lead to poor model performance, which has been under-explored. To address these issues, we propose a new tactics and techniques classification model based on adversarial contrastive learning and meta-path (TTC-ACLM). In TTC-ACLM, a novel text representation learning module is first designed. It includes pre-trained language model (PLM) and contrastive adversarial methods, which can better adapt to categories with smaller sample sizes while obtaining better text representations. Then, heterogeneous information networks are used to model the rich relationships between texts and labels (tactics and techniques), which can merge additional information, e.g., processes and tools, to address text sparsity. Next, we defined a meta-path based classifier learning module that maps text, tactics, and meta-path based context to a set of classifiers, which are applied to the text representation generated by the text representation module for better classification. Finally, the classification performance is further improved through the tactics and techniques correlation enhancement matrix. Through in-depth research, we demonstrate that the proposed model can effectively address the impact of sample imbalance and text sparsity. Extensive experimental results indicate that TTC-ACLM achieves state-of-the-art performance. Yuchun Han, Weiping Wang 0003, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | ASDroid: Resisting Evolving Android Malware With API Clusters Derived From Source CodeabstractMachine learning-based Android malware detection has consistently demonstrated superior results. However, with the continual evolution of the Android framework, the efficacy of the deployed models declines markedly. Existing solutions necessitate frequent and expensive model retraining to resist the constant evolution of malware accompanying Android framework updates. To address this, we introduce a solution called ASDroid, which generalizes specific APIs into similar API clusters to counteract evolving Android malware threats. One primary challenge lies in identifying analogous API clusters that correspond to specific APIs. Our approach involves extracting semantic information from open-source API source code to construct a heterogeneous information graph, and utilizing embedding algorithms to obtain semantic vector representations of APIs. APIs that are close in embedding distance are presumed to have similar semantics. Our dataset encompasses Android applications spanning nine years from 2011 to 2019. In comparison to existing Android malware detection model aging mitigation solutions like APIGraph, SDAC and MaMaDroid, ASDroid demonstrates greater accuracy and more effective at resisting continuously evolving malware. Qihua Hu, Weiping Wang 0003, Hong Song 0004, Song Guo 0001, Jian Zhang 0048, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Building Trust: Security Analysis in IoT Pairing StagesabstractWith the popularity of smart homes, the security issues of IoT devices have garnered significant attention, particularly the device pairing process, which is crucial for secure access and authorized use. However, current research on the communication security during this process remains insufficient. This paper aims to thoroughly analyze the security of the IoT device pairing process. The pairing process is first described using a state transfer model and divided into four phases: device discovery, device networking, remote authentication and remote binding. Subsequently, the different implementations adopted by different vendors in each specific phase are analyzed for the security vulnerabilities they may cause. These vulnerabilities are verified through experimental tests, involving the observation of multiple real devices, monitoring of traffic data, and application of attack methods, revealing existing vulnerabilities and deficiencies in some devices. Finally, based on the experimental results, targeted security improvement recommendations are proposed to enhance the overall security of the devices. Yingjie Hu 0005, Weiping Wang 0003, Shigeng Zhang, Hong Song 0004 |
MSN | 2 |
| 2024 | SimLog: System Log Anomaly Detection Method Based on SimhashabstractEnterprises face increasingly complex and frequent security threats, presenting significant challenges for timely prevention and response. Traditional log-based intrusion detection systems often rely on known attack signatures, limiting their ability to detect novel or evolving threats. Supervised anomaly detection methods, while leveraging machine learning techniques, are constrained by the scarcity of labeled attack samples, leading to gaps in detecting real-world attack variations. To address these limitations, this paper proposes a lightweight anomaly detection framework tailored for relatively stable server environments. The approach constructs provenance graphs from audit logs, extracts local subgraphs centered on process nodes, and utilizes Simhash for semantic embedding and frequency analysis. By combining locality-sensitive hashing with the K-medoids clustering algorithm, the method establishes a robust normal behavior model to detect anomalies. Experimental evaluations on public datasets and high-performance computing platforms demonstrate that the proposed method achieves 97% detection accuracy while significantly reducing the time costs compared to existing methods. Weiping Wang 0003, Yulu Hong, Hong Song 0004, Shigeng Zhang |
TrustCom | 1 |
| 2024 | IoT Device Fingerprinting From Periodic Traffic Using Locality-Sensitive HashingabstractWith the widespread adoption of IoT devices, their inadequate security measures make them increasingly susceptible to malicious attacks. Consequently, accurate device identification has become a critical task for safeguarding network security and privacy. This paper introduces IFPH, a novel method for IoT device fingerprinting and identification based on periodic traffic payload hashing. By exploiting the inherent periodicity in idle traffic, IFPH uses Discrete Fourier Transform (DFT) to extract the traffic's periodicity and applies Locality-Sensitive Hashing (LSH) to process packet payloads within each period. This method generates distinctive device fingerprints, facilitating efficient and reliable device identification. Unlike previous methods, IFPH addresses the inaccuracies associated with fixed-time window fingerprinting and eliminates the need for complex feature extraction or model training. Experimental results reveal that IFPH surpasses existing techniques, achieving accuracy and recall rates exceeding 95% on publicly available datasets. Jianhui Ming, Weiping Wang 0003, Yingjie Hu 0005, Shigeng Zhang |
TrustCom | 2 |
| 2024 | UCG: A Universal Cross-Domain Generator for Transferable Adversarial ExamplesabstractGenerating transferable adversarial examples is a challenging issue in adversarial example attacks. Existing works on transferable adversarial examples generation mainly focus on models with similar architectures and trained on the same data domain. However, in practice, information such as the model architecture type and training data domain is unlikely to be revealed in deployed models. In this work, we introduce the Universal Cross-domain Generator (UCG), a pioneering framework for transferable adversarial examples that is the first to simultaneously address both cross-domain and cross-architecture challenges in adversarial attacks. The design of UCG is mainly inspired by two key observations. First, there exists some commonality in attention regions even when the structures of models are different. Second, there exists prevalent instability of intermediate-feature maps across cross-domain models. We accordingly design anattention transfermechanism and aroughness abatementmechanism to enhance the cross-architecture and cross-domain transferability of the generated adversarial examples. Moreover, we propose anintegrated transformation processingtechnique to improve the transferability of the generated adversarial examples under different transformations. Experimental results demonstrate that, compared with state-of- the-art solutions, UCG improves the average transferable attack success rate by 15.3%, 7.9%, and 8.2% in the cross-architecture task (convolutional neural networks (CNNs) to vision transformers (ViTs)), coarse-grained cross-domain tasks, and fine-grained cross-domain tasks, respectively. Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Foolmix: Strengthen the Transferability of Adversarial Examples by Dual-Blending and Direction Update StrategyabstractAdversarial example attacks are deemed to be a serious threat to deep neural network (DNN) models. Generating adversarial examples in white-box settings has been well-studied, however, it remains challenging to generate transferable adversarial examples that successfully attack black-box models. This work proposes Foolmix, a novel method for generating transferable adversarial examples for black-box attacks. The design of Foolmix is inspired by our observation that adversarial examples with high transferability usually carry multi-class features in the latent space of DNN models. Thus, we propose a dual-blending strategy that blends the image with a set of random pixel-blocks and blends the gradient by calculating the loss of the blended image for both the ground-truth label and a set of random labels. The dual-blending strategy pressures the example to penetrate multiple class regions and gain multi-class features in the latent space, greatly enhancing the transferability of the generated adversarial example. However, the randomness in the blending process might also pressure the example to approach the boundary of the original class region, which lowers the robustness of the example. To mitigate this problem, we further propose an update method in the starting forward direction to guide the generated adversarial example to go deep into multi-class adversarial regions while being globally far away from the original class region. Compared to state-of-the-art transformation-based attacks, Foolmix significantly enhances the transferability of generated adversarial examples, boosting the average transferable attack success rate by 13.2% and 16.9% on mainstream CNNs and ViTs respectively, while achieving better defense breakthrough ability. Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | RF-Siamese: Approaching Accurate RFID Gesture Recognition With One SampleabstractPerforming accurate sensing in diverse environments is a challenging issue in wireless sensing technologies. Existing solutions usually require collecting a large number of samples to train a classifier for every environment, or further assume similar sample distribution between different environments such that a model trained in one environment can be transferred to another. In this paper, we propose RF-Siamese, an RFID-based gesture sensing approach that achieves comparable accuracy to existing solutions but requires only a few samples in each eivironment. RF-Siamese leverages Siamese networks to distinguish different gestures with only a small number of samples and is enhanced by several novel designs to achieve high accuracy in diverse environments. First, the network structure and parameters (e.g., loss function and distance metric) are carefully designed to be suitable for RFID gesture recognition. Second, a permutation-based dataset generation strategy is proposed to make full use of the collected samples to enhance the recognition accuracy. Third, a template matching method is proposed to extend the Siamese network to classify multiple gestures. Extensive experiments on commercial RFID devices demonstrate that RF-Siamese achieves a high accuracy of 0.93 with only one sample of each gesture when recognizing 18 different gestures, while state-of-the-art approaches based on transfer learning and meta learning achieve an accuracy of only 0.59 and 0.70, respectively. Zijing Ma, Shigeng Zhang, Jia Liu 0008, Xuan Liu 0001, Weiping Wang 0003, Jianxin Wang 0001, Song Guo 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | TransAST: A Machine Translation-Based Approach for Obfuscated Malicious JavaScript DetectionabstractAs an essential part of the website, JavaScript greatly enriches its functions. At the same time, JavaScript has become the most common attack payload on malicious websites. Although researchers are constantly proposing methods to detect malicious JavaScript, the emergence of obfuscation technology makes it difficult for previous approaches to detect disguised malicious JavaScript effectively. To solve this problem, we find that there are fixed templates for generating obfuscated code, which makes the original and obfuscated script have a mapping relationship in their structure. The structure information of the code is critical for malicious detection. Therefore, this paper proposes TransAST, a novel static detection method for obfuscated malicious JavaScript. Our approach's key is restoring the obfuscated JavaScript structure information by training the machine translation model. The experiment shows it can achieve 91.35% accuracy and 94.57% recall in the public dataset, which is 5.5% and 10.94% higher than the existing optimal method. Weiping Wang 0003, Zixian Chen, Hong Song 0004, Shigeng Zhang |
DSN | 2 |
| 2023 | Secure Fractional Repetition Codes for Distributed Storage SystemsabstractFractional Repetition (FR) codes are a class of exact-repair regenerating codes known for their ability to minimize repair bandwidth and provide uncoded repair capability. However, the table-based repair mechanism employed by FR codes brings both advantages and challenges. While it enables FR codes to exceed the storage-bandwidth trade-off, it also exposes them to potential information leakage and makes traditional security methods less effective. In this paper, we address the issue of securing FR codes against eavesdroppers who can access the content of a subset of storage nodes. To mitigate the risk of information leakage, we propose a novel code construction that enhances the security of FR codes in a flexible manner. Zhihang Deng, Bing Zhu 0003, Kenneth W. Shum, Weiping Wang 0003 |
GLOBECOM | 4 |
| 2023 | CMMR: A Composite Multidimensional Models Robustness Evaluation Framework for Deep Learning
Wanyi Liu, Shigeng Zhang, Weiping Wang 0003, Jian Zhang 0048, Xuan Liu 0001 |
ICA3PP (5) | 3 |
| 2023 | ISAA: Boost Repair Process by Constructing the Degree Constrained Optimal Repair Tree for Erasure-coded SystemsabstractTo ensure data reliability, large-scale distributed systems usually adopt erasure codes to restore failed nodes. However, existing erasure-coded repair strategies will cause heavy network traffics, which will increase the repair time. In order to boost the repair process, we consider optimizing the repair path which can be abstracted to a repair tree. Moreover, we add a degree constraint to each node to avoid local congestion. In this paper, we study the degree constrained optimal repair tree, which is an NP-hard problem. Current methods cannot find the optimal solution in a short time in complex non-uniform bandwidth networks. To obtain the optimal repair tree, an improved simulated annealing algorithm (ISAA) based on the Prufer code representation is proposed in this paper. In addition, we simulate the repair process of erasure codes in a non-uniform bandwidth network and experiments show that the repair time reduction can reach up to 66.4% and 88.6% with ISAA over Repair Pipelining and Partial-Parallel-Repair. Xianzhi Du, Bing Zhu 0003, Zhihang Deng, Kenneth W. Shum, Weiping Wang 0003 |
ICPADS | 5 |
| 2023 | Accurate IoT Device Identification based on A Few Network TrafficabstractThe number of devices connected to the Internet has been exploding in recent years, and the wide range of device types poses a serious challenge for asset management and maintenance. We need to know if IoT devices are under cyberattack and if there are devices that violate our privacy, such as pinhole cameras. Traffic-oriented IoT device type identification has become an effective method to prevent cyberattacks and manage assets, but at this stage, in the face of the proliferation of novel IoT devices, the current mainstream IoT device type identification methods are difficult to identify them successfully. At the same time, for a significant number of lightweight IoT devices, most identification methods are simply unable to make correct identifications because the traffic generated by these devices is too little. In this paper, we propose IoT-Siamese, a type identification method for IoT devices based on few-shot traffic, which mainly relies on Siamese network to solve the problem of few samples. Experiments show that our proposed identification method has high identification accuracy for those devices that generate a small volume of traffic, and effectively identify novel devices that join the network. Shigeng Zhang, Jianjiang Yu, Xuan Liu 0001, Weiping Wang 0003 |
IWQoS | 5 |
| 2023 | MPS: A Multiple Poisoned Samples Selection Strategy in Backdoor AttackabstractRecently there has been many studies on backdoor attacks, which involve injecting poisoned samples into the training set in order to embed backdoors into the model. Existing multiple poisoned samples attacks usually randomly select a subset from clean samples to generate the poisoned samples. Filtering-and-Updating Strategy (FUS) has shown that the poisoning efficiency of each poisoned sample is inconsistent and random selection is not optimal. However, FUS does not fully considered the selection of multiple poisoned samples, there are still some issues with the selection of multiple poisoned samples. In this paper, we formulate the selection of multiple types of poisoned samples as a multi-objective optimization problem and proposed a Multiple Poisoned Samples Selection Strategy (MPS) to solve the issue. Unlike FUS, we consider the potential of clean samples that are not selected as to become efficient poisoned samples. Specifically, we use a weight-based contribution approach to calculate the contribution of each sample (clean sample and poisoned sample) during the training process from multiple dimensions. Finally, based on the greedy approach, we retain a subset of samples with the largest contribution in each dimension through iterations. We evaluate the effectiveness of MPS on various attack methods, including BadNet, Blended, ISSBA, and WaNet, as well as benchmark datasets. The experimental results on CIFAR-10 and GTSRB show that MPS can increase the attack strength by 1.45% to 18.34% compared to RSS and 0.43% to 10.84% compared to FUS in multiple poisoned samples attacks, thereby enhancing the stealthiness of the attack. Meanwhile, MPS is suitable for black-box settings, meaning that poisoned samples selected in one setting can be applied to other settings. Weihong Zou, Shigeng Zhang, Weiping Wang 0003, Jian Zhang 0048, Xuan Liu 0001 |
TrustCom | 3 |
| 2023 | Practical periodic strategy for 40/100 Gbps Energy Efficient Ethernet
Wanchun Jiang, Renfu Yao, Kaiqin Liao, Yulong Yan, Jiawei Huang 0001, Weiping Wang 0003, Jianxin Wang 0001 |
Comput. Networks | 6 |
| 2023 | LSD: Adversarial Examples Detection Based on Label Sequences DiscrepancyabstractDeep neural network (DNN) models have been widely used in many tasks due to their superior performance. However, DNN models are usually vulnerable to adversarial example attacks, which limits their applications in many safety-critic scenarios. How to effectively detect adversarial examples to enhance the robustness of DNN models has attracted much attention in recent years. Most adversarial example detection methods require modifying or retraining the model, which is impractical and reduces the classification accuracy of normal examples. In this paper, we propose an adversarial example detection approach that does not require modification of the DNN models and meanwhile retains the classification accuracy of normal examples. The key observation is that when we transform the input example with some operations (e.g., masking a pixel with a reference value), feed the transformed example to the target model, and use the output of the intermediate layers to predict the label of the example, the generated label sequences of adversarial examples will be extremely discrepant but the label sequences of normal examples keep nearly unchanged. Motivated by this observation, we design an approach to detect adversarial examples based on the label sequence discrepancy (LSD) of the given examples. The experimental results against five mainstream adversarial attacks on three benchmark datasets demonstrate that LSD outperforms the state-of-the-art solutions in the detection rate of adversarial examples. Moreover, LSD performs well at various confidence levels and exhibits good generalizability between different attacks. Shigeng Zhang, Chengyao Hua, Zhetao Li, Yanchun Li, Xuan Liu 0001, Kai Chen 0012, Zhankai Li, Weiping Wang 0003 |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2023 | Real-Time and Accurate Gesture Recognition With Commercial RFID DevicesabstractGesture recognition based on radio frequency identification (RFID) has attracted much research attention in recent years. Most existing RFID-based gesture recognition approaches use signal profile matching to distinguish different gestures, which incur large recognition latency and fail to support real-time applications. In this paper, we design and implement ReActor, a real-time and accurate gesture recognition system that recognizes a user's gestures with low latency and high accuracy even when the gestures'speed varies. ReActor combines the time-domain statistical features and the frequency-domain features to precisely represent the signal profile corresponding to different gestures. To maintain high accuracy across different environments, we preprocess the signals to remove reflection signals from surrounding objects and use only the signals related to gestures to train the classifier. Moreover, we train a classifier to predict the speed of the gesture and feed the extracted features to different classifiers according to the speed. We implement ReActor and evaluate its performance in different scenarios. Experimental results show that ReActor achieves an average accuracy of 97.2% in recognizing 18 different gestures with an average latency of 72 ms, more than two orders of magnitude faster than approaches based on profile template matching. Shigeng Zhang, Zijing Ma, Xiaoyan Kui, Xuan Liu 0001, Weiping Wang 0003, Jianxin Wang 0001, Song Guo 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2022 | WBA: A Warping-based Approach to Generating Imperceptible Adversarial ExamplesabstractThe human can easily recognize the incongruous parts of an image, for example, perturbations unrelated to the image itself, but are poor at spotting the small geometric transformations. However, in terms of the robustness of deep neural networks (DNNs), the ability to properly recognize objects with small geometric transformations is still a challenge. In this work, we investigate the problem from the perspective of adversarial attacks: does the performance of DNNs degrade even when small geometric transformations are applied to images? To this end, we propose a novel adversarial attack method, called WBA, a Warping-Based Adversarial attack method, which does not introduce information independent of the original images but manipulates the existing pixels of the images by elastic warping transformations to generate adversarial examples that are imperceptible to the human eye. At the same time, existing adversarial attacks typically generate adversarial examples by modifying pixels in the spatial domain of the image, the addition of such perturbations introduces extra information unrelated to the image itself and is easily detected by the naked eyes. We demonstrate the effectiveness of WBA by extensive experiments on commonly used datasets, including MNIST, CIFAR10, and ImageNet. The results show that WBA can quickly generate adversarial examples with the highest adversarial strength, consumes less time, and can be comparable to optimization-based adversarial attack methods in image perception evaluation metrics such as LPIPS, SSIM, and far more than gradient direction-based iterative methods. Chengyao Hua, Shigeng Zhang, Weiping Wang 0003, Zhankai Li, Jian Zhang 0048 |
TrustCom | 3 |
| 2022 | HashDroid:Extraction of malicious features of Android applications based on function call graph pruningabstractWith the Android system becoming the most popular operating system for mobile smart terminals, it is more likely to be targeted by malware. Therefore, many researches of malicous detection have emerged. Most of the features extracted of current malicious detection are discrete, such as single permission, single API, single component, API sequences and so on. These features can only detect the maliciousness of Android applications, but cannot characterize the malicious behavior of Android applications through these features. In this paper,we propose a method to automatically mine malicious features by pruning the function call graph(FCG) of Android applications. These extracted features not only have a good representation for the malicious behavior of Android applications, but also can efficiently detect the malicious. The method uses simhash to characterize the pruned subgraphs of FCG, and selects the subgraphs which play a decisive role in determining maliciousness as malicious features. These malicious features are then used for malicious detection of Android applications. The verification on public datasets shows that our method has a good effect of more than 97% in malicous detection of Android applications. Weiping Wang 0003, Hong Song 0004, Shigeng Zhang, Yulu Hong |
TrustCom | 2 |
| 2022 | High-Rate Constructions of Exact-Repair Regenerating CodesabstractRegenerating codes are a class of distributed storage codes proposed to reduce the bandwidth consumption in the node repair process. In this paper, we present explicitly a construction of exact-repair regenerating codes, which is a two-layer encoding structure that consists of concatenating an outer scalar maximum distance separable (MDS) code followed by an inner tailor-made MDS array code. These coded symbols are distributed across the storage nodes based on a family of combinatorial objects termed t-designs, and this sophisticated symbol placement enables that a failed node can be repaired by simple data transfer. Furthermore, our proposed regenerating codes generally have a high code rate and extend the parameter values of existing constructions. Bing Zhu 0003, Xuyu Zhao, Weiping Wang 0003 |
WCNC | 4 |
| 2022 | An Improved Bound and Singleton-Optimal Constructions of Fractional Repetition CodesabstractFractional repetition (FR) codes are a class of repair efficient erasure codes that can recover a failed storage node with both optimal repair bandwidth and complexity. In this paper, we study the minimum distance of FR codes, which is the smallest number of nodes whose failure leads to the unrecoverable loss of the stored file. We derive a new upper bound on the minimum distance of FR codes, which is tighter than the Singleton bound and a Singleton-like bound that takes locality into account. Based on regular graphs and combinatorial designs, several families of FR codes with optimal minimum distance are obtained. Bing Zhu 0003, Kenneth W. Shum, Weiping Wang 0003, Jianxin Wang 0001 |
IEEE Trans. Commun. | 3 |
| 2021 | Square Fractional Repetition Codes for Distributed Storage Systems
Bing Zhu 0003, Shigeng Zhang, Weiping Wang 0003 |
ICA3PP (2) | 3 |
| 2021 | Expandable Fractional Repetition Codes for Distributed Storage SystemsabstractModern distributed storage systems are increasingly implementing erasure codes to obtain better storage performance. In such systems, it is desirable to regenerate a failed storage node in a cost-effective manner since node failures occur frequently in real-world storage networks. Fractional repetition (FR) codes are a special class of regenerating codes that enable efficient recovery of failed storage nodes. In this paper, we introduce expandable FR codes, wherein both the number of storage nodes and the capacity of each node in the storage systems can be readily expanded. We present explicit constructions of expandable FR codes by applying two families of combinatorial structures called embeddable quasi-residual designs and extendible t-designs. Moreover, we study the property of constructed codes for some special scenarios. Bing Zhu 0003, Shigeng Zhang, Weiping Wang 0003 |
ITW | 3 |
| 2021 | Fast Application Activity Recognition with Encrypted Traffic
Shigeng Zhang, Weiping Wang 0003 |
WASA (2) | 4 |
| 2021 | A Secure Scheme Based on One-Way Associated Key Management Model in Wireless Sensor NetworksabstractTo achieve security in wireless sensor networks (WSNs), it is important to be able to encrypt messages sent among sensor nodes by using shared keys between them. Due to resource constraints, achieving such key agreement in WSNs is nontrivial. Previous research indicates that key management schemes using deployment knowledge can significantly improve the performance of WSNs. Nevertheless, in these schemes, resilient local connectivity and resilient global connectivity become unstable when deployment error changes. To resolve the above problem, in this article, a one-way associated key management model is proposed. In this model, the key pool consists of two layers: 1) the global layer and 2) the local layer. According to different deployment errors, the number of keys allocated from the global key pool and local key pools can be dynamically adjusted, thereby improving the stability of networks' performance. In multiphase sensor networks, analysis and simulation indicate that our scheme has better adaptability in applications where deployment error changes as compared with related schemes. Sujun Li, Boqing Zhou, Qinqin Hu, Jianxin Wang 0001, Jingguo Dai, Weiping Wang 0003, Huiyong Yuan, Jie Wu 0001 |
IEEE Internet Things J. | 6 |
| 2021 | An Exploit Kits Detection Approach Based on HTTP Message GraphabstractThe exploit kits (EKs) are used by attackers to distribute malware automatically and silently. Existing approaches to EKs detection usually need to perform dynamic analysis on the content contained in the network traffic, which requires dumping all the network traffic and thus causes high detection overhead. Although some approaches detect EKs based on static analysis, they usually fail to restore the complete attack path because of the obstruction set by the attackers. In this paper, we propose an approach that can detect EKs based on only information extracted by static analysis. Our method builds a graph for web sessions and extracts features from the graph to perform EKs detection. The built graph catches important structural characteristics of the interaction during EK attacks that were not revealed in existing methods, with which EKs can be detected with high accuracy. The experiments show that our method works well in both the ground-truth datasets and the latest practical cases. Our method can also identify the malicious websites concealed in EKs, which can further improve the efficiency of analysis. Weiping Wang 0003, Shigeng Zhang, Kai Chen 0012 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | On the Optimal Minimum Distance of Fractional Repetition CodesabstractFractional repetition (FR) codes are a class of repair efficient erasure codes that can recover a failed storage node with both optimal repair bandwidth and complexity. In this paper, we focus on the minimum distance of FR codes, which is the smallest number of nodes whose failure leads to the unrecoverable loss of stored files. We consider upper bounds on the minimum distance and present several families of FR codes attaining these bounds. The optimal constructions are derived from regular graphs and combinatorial designs, respectively. Bing Zhu 0003, Kenneth W. Shum, Weiping Wang 0003, Jianxin Wang 0001 |
GLOBECOM | 3 |
| 2020 | WSAD: An Unsupervised Web Session Anomaly Detection Methodabstractservers in the Internet are vulnerable to Web attacks, to detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on a single HTTP request, which is easy to ignore the attack behavior within a period of time, such as brute-force password cracking attack. In this paper, we propose an unsupervised W eb S ession A nomaly D etection method called WSAD. WSAD uses ten features of web session to perform anomaly detection. After extracting the ten features, WSAD uses the DBSCAN algorithm to cluster the features of each session and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of WSAD on several datasets from multiple real websites of a company. The results indicate that WSAD could detect malicious behaviors that could not be detected by Web Application Firewall, and it almost has no false positives. Yizhen Sun, Yiman Xie, Weiping Wang 0003, Shigeng Zhang, Yating Chen |
MSN | 3 |
| 2020 | RPAD: An Unsupervised HTTP Request Parameter Anomaly Detection MethodabstractWeb servers in the Internet are vulnerable to Web attacks. A general way to launch Web attacks is to carry attack payloads in HTTP request parameters, e.g. SQL Injection and XSS attacks. To detect Web attacks, a commonly used method is to detect anomalies in the request parameters by making regular-expression-based matching rules for the parameters based on known security threats. However, such methods cannot detect unknown anomalies well and they can also be easily bypassed by using techniques like transcoding. Moreover, existing anomaly detection methods are usually based on supervised learning methods that require a large number of high-quality labelled samples as training sets, which are difficult to obtain in real situations. In this paper, we propose an unsupervised HTTP Request Parameter Anomaly Detection method called RPAD. RPAD uses five features of HTTP request parameters to perform anomaly detection including type, length, number of tokens, encoding type and character feature. After extracting the five features, RPAD uses the DBSCAN algorithm to cluster the parameters of each target access request and outputs the outliers found in the clustering process as anomalies. We evaluate the performance of RPAD on several datasets from multiple real websites of a Cyber Security Company. The results indicate that RPAD is highly efficient in detecting deviating abnormal parameter values with an accuracy of 99%. Yizhen Sun, Yiman Xie, Weiping Wang 0003, Shigeng Zhang, Jingchuan Feng |
TrustCom | 3 |
| 2020 | Accurate human activity recognition with multi-task learning
Yinggang Li, Shigeng Zhang, Bing Zhu 0003, Weiping Wang 0003 |
CCF Trans. Pervasive Comput. Interact. | 4 |
| 2020 | SuPoolVisor: a visual analytics system for mining pool surveillanceabstractCryptocurrencies represented by Bitcoin have fully demonstrated their advantages and great potential in payment and monetary systems during the last decade. The mining pool, which is considered the source of Bitcoin, is the cornerstone of market stability. The surveillance of the mining pool can help regulators effectively assess the overall health of Bitcoin and issues. However, the anonymity of mining-pool miners and the difficulty of analyzing large numbers of transactions limit in-depth analysis. It is also a challenge to achieve intuitive and comprehensive monitoring of multi-source heterogeneous data. In this study, we present SuPoolVisor, an interactive visual analytics system that supports surveillance of the mining pool and de-anonymization by visual reasoning. SuPoolVisor is divided into pool level and address level. At the pool level, we use a sorted stream graph to illustrate the evolution of computing power of pools over time, and glyphs are designed in two other views to demonstrate the influence scope of the mining pool and the migration of pool members. At the address level, we use a force-directed graph and a massive sequence view to present the dynamic address network in the mining pool. Particularly, these two views, together with the Radviz view, support an iterative visual reasoning process for de-anonymization of pool members and provide interactions for cross-view analysis and identity marking. Effectiveness and usability of SuPoolVisor are demonstrated using three cases, in which we cooperate closely with experts in this field. Jiazhi Xia, Guang Jiang, Ying Zhao 0001, Xiaoyan Kui, Weiping Wang 0003 |
Frontiers Inf. Technol. Electron. Eng. | 10 |
| 2020 | LSCDroid: Malware Detection Based on Local Sensitive API Invocation SequencesabstractMalware detection is an important and challenging issue in the Android ecosystem. Many approaches have been proposed to distinguish malicious applications from benign ones, but few of them can represent the behavior patterns of malicious applications and help understand their intention. In this paper, we propose LSCDroid, a malware detecting approach that cannot only detect malware but also help understand the malware's intention by analyzing its behavior patterns. LSCDroid uses local sensitive application programming interface (API) invocation (LSAI) sequences as features to detect malware and represent different malicious behavior patterns. We first extract LSAI sequences of malicious applications based on their function-call graphs. After removing redundant sequences and merging fragmented ones, we obtain a set of LSAI sequences that can be used to effectively detect malicious applications. We further manually analyze the semantic of the obtained sequences and find that a large fraction of them can be used to characterize different behavior patterns of malware and help understand their intention, e.g., sending SMS message stealthily, obtaining geographical information, remote control, and root privilege. We design a machine learning based malware detection and classification algorithm by taking the obtained sequences as input features. Experimental results show that the accuracy and recall of LSCDroid on multiple datasets are both higher than 0.98. Meanwhile, LSCDroid can classify malware families with an accuracy higher than 0.96. Moreover, LSCDroid can represent the behavior patterns and help understand intention of malware by mapping their LSAI sequences to some typical malicious behaviors. Weiping Wang 0003, Jianjian Wei, Shigeng Zhang |
IEEE Trans. Reliab. | 1 |
| 2019 | On the Optimal Reconstruction Degree of Fractional Repetition CodesabstractFractional repetition (FR) codes form a special class of minimum bandwidth regenerating codes by providing uncoded repairs with a table-based repair model. In this paper, we focus on a lower bound on the reconstruction degree of FR codes, which is the smallest number of storage nodes required for data retrieval. We show that for an FR code with reconstruction degree attaining this lower bound, the corresponding dual FR code is optimal with respect to an upper bound on the file size, and vice versa. Using this duality relationship, we present several families of FR codes with optimal reconstruction degree. Bing Zhu 0003, Kenneth W. Shum, Hui Li 0022, Weiping Wang 0003 |
ISIT | 4 |
| 2019 | VDetector: Detecting Vulnerability Based on Inter-Component Data Flows in Android ApplicationsabstractWith the popularity of Android devices and the improvement of intelligence of mobile phones, our life becomes more and more convenient. Meanwhile, the popularity brings new challenges to Android security, especially the application vulnerabilities. These vulnerabilities may lead to sensitive data leaks. To address this issue, researchers have proposed methods to detect the vulnerabilities in Android applications. But most of them only detect one type of vulnerabilities. In this paper, we propose VDetector, a data flow tracking based method for detecting three types of vulnerabilities, Log Leak Vulnerability, Content Provider Vulnerability, and Inter-Components Communication Vulnerability. Based on the reasons of the three types of vulnerabilities, VDetector transforms the detection into the data flow tracking. We first extend the source and sink sets corresponding to the vulnerabilities. Then we explore whether there are paths between the sources and the sinks. If there are paths, it indicates that the vulnerabilities exist. At last, three datasets are used for experiments and the result indicates that VDetector effectively finds such android application vulnerabilities above. Xuchong Liu, Weiping Wang 0003 |
MSN | 3 |
| 2019 | An Efficient Authentication Scheme Based on Deployment Knowledge Against Mobile Sink Replication Attack in UWSNsabstractUnattended wireless sensor networks (UWSNs) are vulnerable to mobile sink (MS) replication attack. In this attack, using the compromised key information, an attacker can collect data from networks by impersonating sinks. To resist such an attack, some schemes have been proposed. To improve the resilience of MS replication attack of these schemes, we can integrate them with schemes based on deployment knowledge. However, there are the following defects: 1) the probability of mutual authentication between a MS and a sensor node is less than 1 and 2) during the authentication phase, the energy consumption of sensor nodes increases significantly as the deployment area expands. In this paper, we construct 3-D backward key chains based on deployment knowledge and propose a new authentication scheme based on these. As compared with these existing related schemes, the detailed theory analysis and simulation results indicate that the scheme can ensure that a MS can be authenticated by sensor nodes, and can improve the resilience of networks' MS replication attack with low energy consumption. Boqing Zhou, Sujun Li, Weiping Wang 0003, Jianxin Wang 0001, Jie Wu 0001 |
IEEE Internet Things J. | 3 |
| 2019 | PDRCNN: Precise Phishing Detection with Recurrent Convolutional Neural NetworksabstractThrough well-designed counterfeit websites, phishing induces online users to visit forged web pages to obtain their private sensitive information, e.g., account number and password. Existing antiphishing approaches are mostly based on page-related features, which require to crawl content of web pages as well as accessing third-party search engines or DNS services. This not only leads to their low efficiency in detecting phishing but also makes them rely on network environment and third-party services heavily. In this paper, we propose a fast phishing website detection approach called PDRCNN that relies only on the URL of the website. PDRCNN neither needs to retrieve content of the target website nor uses any third-party services as previous approaches do. It encodes the information of an URL into a two-dimensional tensor and feeds the tensor into a novelly designed deep learning neural network to classify the original URL. We first use a bidirectional LSTM network to extract global features of the constructed tensor and give all string information to each character in the URL. After that, we use a CNN to automatically judge which characters play key roles in phishing detection, capture the key components of the URL, and compress the extracted features into a fixed length vector space. By combining the two types of networks, PDRCNN achieves better performance than just using either one of them. We built a dataset containing nearly 500,000 URLs which are obtained through Alexa and PhishTank. Experimental results show that PDRCNN achieves a detection accuracy of 97% and an AUC value of 99%, which is much better than state-of-the-art approaches. Furthermore, the recognition process is very fast: on the trained PDRCNN model, the average per URL detection time only cost 0.4 ms. Weiping Wang 0003, Shigeng Zhang |
Secur. Commun. Networks | 1 |
| 2019 | BridgeTaint: A Bi-Directional Dynamic Taint Tracking Method for JavaScript Bridges in Android Hybrid ApplicationsabstractHybrid applications (apps) are becoming more and more popular due to their cross-platform capabilities and high performance. These apps use the JavaScript (JS) bridge communication scheme to interoperate between native code and Web code. Although greatly extending the functionalities of hybrid apps by enabling cross-language invocations and making them more powerful, the bridge communication scheme might also cause some new security issues, e.g., cross-language code injection attacks and privacy leaks. In this paper, we propose BridgeTaint, a bi-directional dynamic taint tracking method that can detect bridge security issues in hybrid apps. BridgeTaint uses a method different from existing ones to track tainted data: it records the taint information of sensitive data when the data are transmitted through the bridge, and uses a cross-language taint mapping method to restore the taint tags of corresponding data. Such a novel design enables BridgeTaint to dynamically track tainted data during the execution of the app and analyze hybrid apps developed using frameworks, which cannot be done with existing solutions based on static code analyses. Based on BridgeTaint, we implement the BridgeInspector tool to detect cross-language privacy leaks and code injection attacks in hybrid apps using JS bridges. A benchmark called BridgeBench is also developed for bridge communication security test. The experimental results on BridgeBench and 1172 apps from Android market demonstrate that BridgeInspector can effectively detect potential privacy leaks and cross-language code injection attacks in hybrid apps using bridge communications. Junyang Bai, Weiping Wang 0003, Shigeng Zhang, Jianxin Wang 0001, Yi Pan 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | A fine-grained rule partition algorithm in cloud data centers
Wei Jiang 0042, Wanchun Jiang, Weiping Wang 0003, Yi Pan 0001, Jianxin Wang 0001 |
J. Netw. Comput. Appl. | 3 |
| 2016 | TD-WS: a threat detection tool of WebSocket and Web Storage in HTML5 websitesabstractAbstract The new features of HTML5 greatly increase the convenience for both web developers and users, but they also bring new security threats. Although the web‐security community has started to analyze the security threats brought by HTML5, little has been performed to address the security threats for the client‐side applications. This paper studies security issues of two popular client‐side primitives: WebSocket and Web Storage. The security threats concerned in this paper are private information stealth through WebSocket and cross‐site scripting vulnerabilities caused by lacking of sanitization for WebSocket messages and Web Storage data. We analyze the unsafe data flows of these two HTML5 primitives in detail. Based on that, we present a threat detection tool called TD‐WS, which can automatically detect the privacy leaks and the cross‐site scripting vulnerabilities in WebSocket and Web Storage applications. The results show that TD‐WS effectively detects the security threats of WebSocket and Web Storage applications. Copyright © 2016 John Wiley & Sons, Ltd. Junyang Bai, Weiping Wang 0003, Mingming Lu, Jianxin Wang 0001 |
Secur. Commun. Networks | 2 |
| 2016 | Code pruning in opportunistic routing through bidirectional coding traffic comparisonabstractAbstract Opportunistic routing (OR) significantly improves transmission reliability and network throughput in wireless mesh networks by utilizing the broadcast nature of the wireless medium. Through the integration of network coding (NC), the complicated coordination to select the best forwarding node (FN) in OR can be bypassed. However, the introduction of NC exacerbates the redundant‐packet‐transmission problem. To mitigate this issue, existing coded OR protocols either adopt the loss‐rate‐based approach, employ orthogonal vectors as coded feedback, or pursue the stream‐based coded OR model. However, these three solutions suffer inaccuracy and obsolescence of the loss‐rate measurement, false‐positive/false‐negative problem, and unavailability of hop‐by‐hop stream‐based OR, respectively. To address the previous problems, we propose a simple but practical coded feedback scheme, cumulative coding coefficient acknowledgement (C3ACK), based on the relevance between forward (coded packets received from upstream nodes) and backward coding traffic (coded packets overheard from downstream nodes), and apply C3ACK to both batch‐based and stream‐based coded OR models in order to prune redundant forward and backward coding traffic. Both testbed evaluation and simulation study show that our code‐pruning schemes can outperform existing approaches in terms of expected throughput and transmission count. Copyright © 2014 John Wiley & Sons, Ltd. Weiping Wang 0003, Xiaozhuan Chen, Mingming Lu, Jianxin Wang 0001, Xi Zhang 0005, Jie Wu 0001 |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | Fair coding for inter-session network coding in wireless mesh networksabstractAbstract Because of the broadcast and overhearing capability of wireless networks, network coding can greatly improve throughput in wireless networks. However, our investigation of existing inter‐session network coding protocols found that the short‐term unfairness that existed in 802.11‐based medium access control (MAC) protocols actually decreases the coding opportunity, which in turn compromises the throughput gain of network coding. To alleviate the negative impact of this unfairness, we propose a coding‐aware cross‐layer heuristic approach to optimize the coordination of network coding and MAC layer protocol, named FairCoding, which can significantly increase coding opportunities for inter‐session network coding through a fair short‐term traffic allocation for different coding flows. Experiment evaluation shows that the proposed mechanism can bring more coding opportunities and improve the total throughput of wireless mesh networks by up to 20%, compared with the coding mechanism, without considering the negative impact of the short‐term unfairness. Copyright © 2015 John Wiley & Sons, Ltd. Weiping Wang 0003, Mingming Lu, Jianxin Wang 0001, Xi Zhang 0005 |
Wirel. Commun. Mob. Comput. | 2 |
| 2015 | A new approach to designing firewall based on multidimensional matrixabstractSummary Firewalls are crucial elements to enhance network security by examining the field value of every packet and decide whether to accept or discard the packet according to the firewall policy. However, the design of firewall policies, especially for enterprise networks, is complex and error‐prone. This paper aims to propose an effective firewall design method to ensure the consistency, compactness and completeness of firewall rules. Specifically, we develop a new designing model, namely firewall design matrix, and the corresponding construction algorithm for mapping firewall rules to firewall design matrix. A firewall generation algorithm is proposed to generate the target firewall rules that are equivalent to the original ones while maintaining the completeness. Theoretical proof and extensive experiments on both real‐world and synthetic firewalls are conducted to evaluate the performance of the proposed method. The results demonstrate that it can achieve a high compression ratio efficiently while maintaining the firewall rules conflict‐free. Copyright © 2013 John Wiley & Sons, Ltd. Yuzhu Cheng, Weiping Wang 0003, Geyong Min, Jianxin Wang 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2013 | Adaptive explicit congestion control based on bandwidth estimation for high bandwidth-delay product networks
Jianxin Wang 0001, Pingping Dong, Jie Chen 0072, Jiawei Huang 0001, Shigeng Zhang, Weiping Wang 0003 |
Comput. Commun. | 6 |
| 2011 | An Explicit Congestion Control Protocol Based on Bandwidth EstimationabstractExplicit feedback based congestion control schemes can capture network congestion status more accurately than pure end-to-end schemes. However, some of such schemes require modifying IP header in order to achieve near optimal performance, which incurs complicated computation in routers as well as makes them difficult to deploy in real networks. In contrast, the VCP protocol achieves good performance by using the two existing ECN bits in the IP header for feedback, but its convergence speed is relatively low due to insufficient congestion feedback. In this paper, we propose VCP-BE, a protocol based on VCP and uses end-to-end bandwidth estimation to obtain high resolution congestion estimation. With the estimated available bandwidth and ECN feedback, VCP-BE adjusts the congestion window more precisely than VCP thus converges much faster. Simulation results show that VCP-BE outperforms VCP and MLCP, achieving high efficiency and reasonable fairness. Jianxin Wang 0001, Jie Chen 0072, Shigeng Zhang, Weiping Wang 0003 |
GLOBECOM | 4 |
| 2011 | DENNC: A Wireless Malicious Detection Approach Based on Network CodingabstractIn wireless networks, communications among nodes are vulnerable to attacks launched by malicious nodes. Presently, Existing malicious node detection approaches either need special hardware or depend on node listening, node encryption or node identity authentication, resulting high costs of networks. In this paper, we present a novel network coding-based malicious detection approach called DENNC for wireless networks. The key idea is to use the characteristic of information exchange to validate the information packets. The neighboring nodes of the sending node may judge the malicious behaviors by checking the correctness of the data packets and related hash value. Our approach requires no superfluity hardware and does not use complicated secret key encryption mechanisms. Analysis reveals that the proposed approach can detect the malicious node in highly probability. Hong Song 0004, Weiping Wang 0003, Luming Yang |
TrustCom | 3 |
| 2009 | An Anonymous Communication Mechanism without Key Infrastructure Based on Multi-Paths Network CodingabstractIn the anonymous communication mechanisms based on key infrastructure, public key or pre-shared key are widely used to set up relay paths and negotiate shared keys in session. Therefore, these systems always have complicated architecture and high key management cost. However, key infrastructure is hard to deployed in distributed environment. Based on multi-paths network coding, this paper firstly proposes a new information slicing and transmitting method ITNC. Then a novel anonymous communication mechanism AC-ITNC without key infrastructure, which is based on ITNC, is presented. In the new mechanism, the anonymous path setup information is sliced into pieces and each piece is coded by the random coding coefficient. The coding coefficients and coded information pieces are delivered along multiple paths, which makes the anonymous relay paths be set up in the case of non-cryptographic scheme. Theoretical analysis and simulation results show that AC-ITNC can significantly improve the security against conspiracy attack in anonymous communication system without key infrastructure. Weiping Wang 0003, Guihua Duan, Jianxin Wang 0001, Jianer Chen |
GLOBECOM | 1 |
| 2009 | Detection and location of malicious nodes based on source coding and multi-path transmission in WSNabstractThere are many security threats in WSN, such as malicious nodes on the transmission paths dropping, fabricating or tampering the forwarded messages. Most of the existing security methods relied on special hardware facilities, mechanism of node monitoring, encryption and authentication technology, which greatly increase the sensorpsilas price or computing and communicating cost in WSN. In this paper, we propose a new method, named as DESCM, which is based on source coding and multi-path transmission. Theoretical analysis shows that DESCM can detect and locate malicious nodes with high probability. Comparing with other methods, DESCM does not need special hardware, encryption or authentication technology, which can detect the malicious nodes with lower cost. Weiping Wang 0003, Jinhong Xu, Jianxin Wang 0001 |
HPCC | 1 |
| 2009 | An analytical model for end-to-end communication channel over PLCN based on QBDs
Guofeng Yan, Jianxin Wang 0001, Weiping Wang 0003 |
Inf. Process. Lett. | 3 |
| 2008 | A New Anonymity Measure Based on Partial EntropyabstractWith the development of Internet applications, a number of anonymous communication systems have been realized to protect the identity of communication participants. Therefore, it is essential to give a theoretically based and practically usable objective numerical measure for the provided level of anonymity. In this paper some typical anonymity measures are analyzed and limitations of these measures was highlighted. Then a new anonymity measure based on partial entropy is proposed, in which the anonymity is measured by using the entropy of the probability distribution of some distinct subjects in anonymity set. The results of analysis and calculation show that the new measure is preferable for anonymity evaluation. Guihua Duan, Weiping Wang 0003, Jianxin Wang 0001, Luming Yang |
ICC | 2 |
| 2008 | A Source-Location Privacy Protocol in WSN Based on Locational AngleabstractIn environments where sensor networks are used to monitor sensitive objects or valuable assets, attackers may use the method of hop-by-hop backtracking to find out the protected objects. This paper proposes a new source protected protocol in WSN, the phantom routing with locational angle (PRLA). In PRLA, inclination angles are introduced and used to direct random walks, which avoids choosing paths harmful to the privacy of source location. Simulation results show that, compared to the phantom single-path routing protocol proposed in the literature, PRLA improves the safety period by up to 50% with minor increase in energy overhead. Weiping Wang 0003, Jianxin Wang 0001 |
ICC | 1 |